On Splunk server (receiver) Download/install Splunk TA for Unix and Linux to the Splunk server (receiver) and enabled it by going to Manager|Apps|Enable

On host you want to collect data from (sender) Download and install the Splunk Universal Forwarder to the Linux host – the assumption is made that this configured and sending data to Splunk, in brief it consisted of the following for RHEL6

Next edit the inputs.conf file located in /opt/splunkforwarder/etc/apps/Splunk_TA_nix/local/ and enable items you wish to monitor by setting the “disabled” attribute to “false” and then restart splunkforwarder.